[Secure-testing-commits] r47282 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Wed Dec 21 15:39:44 UTC 2016
Author: carnil
Date: 2016-12-21 15:39:44 +0000 (Wed, 21 Dec 2016)
New Revision: 47282
Modified:
data/CVE/list
Log:
CVE-2016-10012: mark as low
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-12-21 15:39:01 UTC (rev 47281)
+++ data/CVE/list 2016-12-21 15:39:44 UTC (rev 47282)
@@ -238,7 +238,7 @@
- xen <unfixed> (bug #848713)
NOTE: https://xenbits.xen.org/xsa/advisory-204.html
CVE-2016-10012 [sshd(8): shared memory manager bounds checks that could be elided by some optimising compilers potentially allow attacks against the privileged monitor process from the sandboxed privilege-separation process]
- - openssh <unfixed> (bug #848717)
+ - openssh <unfixed> (low; bug #848717)
[jessie] - openssh <no-dsa> (Minor issue)
NOTE: Fixed in upstream 7.4: https://www.openssh.com/txt/release-7.4
NOTE: http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/monitor.c.diff?r1=1.165&r2=1.166
More information about the Secure-testing-commits
mailing list